Authenticated Sensor Interface Device for Secure Data Transmission

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The secure transmission and storage of data over networks, such as the Internet, are compromised by interception and manipulation risks, particularly for sensitive information like proprietary or classified data, which can be vulnerable to external access and corruption, affecting safety, quality control, and national security.

Innovation Solution

A system utilizing a data aggregate device that encrypts data into independently encrypted packets and transmits them over isolated data paths with optoisolators for one-way transmission, along with a secure data filter that controls optical access using a movable shutter and sensor circuits to authenticate and validate data, preventing external manipulation and ensuring data integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is transmitted over the Internet or network, then communication capability and information exchange are improved, but security and vulnerability to interception/manipulation worsen

Engineering Contradiction:
Improvecommunication capabilityVSAvoiddata security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent divides data into multiple independently encrypted packets that are transmitted through separate isolated data paths. Each packet contains a portion of the original data and can be independently authenticated, so that compromise of one path does not affect the security of the entire data transmission.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an authenticated sensor interface device that acts as an intermediary between the data source and network. This device includes a secure data filter with optical sensors and a data diode that authenticates data before transmission, creating a trusted boundary between the secure internal system and the untrusted network environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If data is stored on devices connected to the Internet, then accessibility and data retrieval are improved, but vulnerability to external access and manipulation worsens

Engineering Contradiction:
Improvedata accessibilityVSAvoidexternal access vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication and validation functions from the networked storage devices and places them in a dedicated secure data filter. This separation allows the storage devices to remain accessible while the authentication mechanism remains isolated from network threats.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs authentication and validation of data before it enters the network or storage systems. The secure data filter authenticates data packets in advance, so that only verified data is transmitted or stored, preventing unauthorized access and manipulation at the source.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If optical sensors are made accessible for data reception, then data transmission capability is improved, but susceptibility to external manipulation and unauthorized access worsens

Engineering Contradiction:
Improvedata transmission capabilityVSAvoidexternal manipulation risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent places the optical sensors behind an isolated data path with a data diode that acts as an intermediary. The diode allows optical signals to pass from the secure internal system to the external network but physically prevents any external signal from entering the sensor, eliminating bidirectional communication vulnerabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional electrical or digital communication interfaces with optical communication. The optical sensors receive data through light signals, which can be physically isolated more effectively than electrical connections, and the optical signals are converted to electrical signals only within the secure boundary of the authenticated sensor interface device.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

The system ensures secure, segregated data transmission to multiple recipients, preventing external interception or manipulation, while the unique codes within encrypted packets authenticate data and prevent replay attacks, maintaining data integrity and security.

Implementation Method 1

Each of the plurality of optoisolators is configured to provide one-way transmission of data from the data aggregate device over one of the plurality of isolated data paths

Methodology Applied
Scientific EffectOptoisolation: Light Emitting Diode

Implementation Method 2

a receiver having one or more optical sensors configured to receive an optical signal encoding the external data

Methodology Applied
Scientific EffectPhotoelectric effect: Photoelectric Effect

Data Source

PatentUS9961108B2Authenticated sensor interface device
Publication Date: 2018.05.01 BATTELLE SAVANNAH RIVER ALLIANCE LLC
  • US9961108B2 patent drawing
  • US9961108B2 patent drawing
  • US9961108B2 patent drawing

AI summary

A system and method for the secure storage and transmission of data is provided. A data aggregate device can be configured to receive secure data from a data source, such as a sensor, and encrypt the secure data using a suitable encryption technique, such as a shared private key technique, a public key encryption technique, a Diffie-Hellman key exchange technique, or other suitable encryption technique. The encrypted secure data can be provided from the data aggregate device to different remote devices over a plurality of segregated or isolated data paths. Each of the isolated data paths can include an optoisolator that is configured to provide one-way transmission of the encrypted secure data from the data aggregate device over the isolated data path. External data can be received through a secure data filter which, by validating the external data, allows for key exchange and other various adjustments from an external source.